CVE-2023-39421: Resortdata Internet Reservation Module Next Generation

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

Affected products

  • Resortdata Internet Reservation Module Next Generation: version 5.4.1.23 only

Published 2023-09-07. Last modified 2026-06-17.